Methodology & About¶
News Agent is a curated cyber-threat and M&A intelligence feed compiled from public reporting for situational awareness. It is produced for private-equity operators and their portfolios. This page explains how to read it โ and, importantly, what it does and does not assert.
Claims are not confirmed breaches¶
A large share of the victim data on this site originates from ransomware / extortion groups' own data-leak sites (DLS). A listing there is a claim by the attacker, not a confirmed breach. Groups recycle, inflate, and re-post entries. We publish these claims because tracking them is standard cyber-threat-intelligence practice โ but we frame them as claims:
- We say an organisation was listed on \<actor>'s leak site or claimed by \<actor>.
- We do not say it was "breached" or "hacked" unless the organisation (or an authoritative source such as CISA, FBI, or Mandiant) has confirmed it.
- Verify before acting. Treat an unverified claim as a lead to investigate, not a fact.
Confidence flags¶
Every tracked record carries a confidence flag:
Severity flags (briefings)¶
Signals confidence (ICD-203)¶
The Signals section tracks emerging trends and behaviour shifts โ not confirmed news โ so it uses a different model than the claim-verification flags above: analytic confidence, adapted from the US intelligence community's ICD-203 standard. It grades how much we trust the judgment, not whether an individual fact is verified.
Each signal also carries a one-line words-of-estimative-probability judgment (e.g. "likely", "roughly even chance") about where the trend goes next โ a separate axis from confidence in the current read. Forum/sentiment sources (Reddit, Hacker News) are treated as anecdotal by default: a single post is ๐ฅ Low on its own; confidence upgrades only once corroborated by a second independent thread or a press source.
Signal lifecycle¶
Signals are living records, not one-off entries. Watching (first observation) โ Strengthening or Fading (as corroboration grows or evidence goes quiet) โ Confirmed-trend or Archived/Confidence-decayed. There is no "wrong" signal here โ only signals whose confidence rises or falls with the evidence. Moving one to the Archive records that corroboration stopped accumulating or confidence declined, not that the original observation was incorrect. Resolved signals move to the Archive โ never deleted โ and are rechecked roughly weekly for resurgence, since a decayed signal sometimes comes back.
Cross-domain convergence¶
A signal that co-occurs with an item in the same window's Geopolitics section or Threat Actor & Campaign Activity โ pointing at the same country or sector โ is flagged with a โก badge. The convergence across independent domains is often the actual early-warning signal; no single domain alone would have surfaced it.
Threat Level composite¶
The home page's Threat Level tile is a 0โ100 weighted composite of three components, each
computed from the data (never hardcoded): breach severity (today's critical-flagged items, weight
0.5), victim volume (disclosed victims over the trailing 30 days, weight 0.3), and actor
concentration (the most-active actor's share of that 30-day volume, weight 0.2), banded into
GUARDED / ELEVATED / HIGH. Like the Signals confidence model, these weights and thresholds are
editorial judgment, not a scientific measure โ calibrated by reviewing the site's own briefing
history so the bands actually discriminate, not derived from an academic index. The methodology is
versioned (THREAT_LEVEL_VERSION in build_site.py); a coefficient or threshold change bumps the
version and gets a line here.
Sourcing standard¶
Every item is attributed with at least one clickable link, and figures are corroborated across independent sources before publication. We prefer primary sources โ vendor releases, SEC 8-Ks, and government advisories โ over aggregators, and file M&A deals by announcement date and breaches by disclosure date. Where a figure cannot be corroborated, we say so rather than inventing it. See the Sources page for the tracked source list and its live reachability status.
Scope¶
Cybersecurity M&A from 2026 onward and notable global incidents, with the US and Europe prioritised. APT / nation-state victims are listed only on authoritative attribution, never on group claims alone.
Feedback: intel@bluesec.io. This is a staging preview โ a prototype for evaluation, not the production feed.